Aug 5 / Dianne Pledgie

New HIPAA Settlement Reflects OCR’s Position that 60-Day Breach Notification Clock Starts at Discovery, Not at Conclusion of Investigation

On July 29, 2026, the Department of Health and Human Services' Office for Civil Rights (OCR) announced a $552,250 settlement with OSF Healthcare System (OSF). OCR found that OSF potentially violated the Breach Notification Rule by waiting until its forensic investigation was complete before notifying patients, rather than notifying patients within 60 days of discovering evidence of the ransomware attack. The OSF settlement makes clear that OCR ties the breach notification deadline to the date of discovery, regardless of how long it takes to complete the investigation.


What Happened

The resolution agreement includes the following timeline of events:

  • April 23, 2021: OSF discovered evidence of a ransomware attack.
  • August 24, 2021: OSF completed its forensic investigation and confirmed the threat actors stole PHI of 53,907 patients.
  • October 1, 2021: OSF notified patients and OCR.


OCR’s investigation indicated that OSF:

  • Failed to conduct an accurate and thorough risk analysis of the potential risks and vulnerabilities to ePHI held by OSF; 
  • Impermissibly disclosed the PHI of 53,907 individuals;
  • Failed to provide timely notification to individuals affected by the breach; and
  • Failed to provide timely notification to the Secretary of HHS that the 2021 ransomware attack resulted in the disclosure of 500 or more individuals' PHI.

Why It Matters for Your Health Center

The Breach Notification Rule requires covered entities to report without unreasonable delay and no later than 60 calendar days from the discovery of the breach. OSF notified patients 38 days after the completion of the forensic investigation and 161 days after the ransomware attack. OSF’s timeline reflects a common assumption: a breach is “discovered” only once the scope and impact are known, often the date the forensic investigation is completed. OCR’s separate citation of OSF’s failure to provide timely notifications indicates the agency does not accept such an interpretation. This settlement agreement indicates that discovery, not confirmation, starts the breach notification clock, and a lengthy forensic investigation does not toll the notification deadline.


Entities facing a ransomware attack or other security incident should:

  • Build their notification timeline around the date the incident was discovered, not the date forensic certainty is achieved;
  • Document when they had sufficient information to notify individuals, and be prepared to show that determination; and
  • Consider a phased notification process – providing initial notification within 60 days of the incident, followed by updates as the forensic investigation is completed.


Join us next week for a two-part webinar series covering every stage of the breach response process, from breach identification and notification requirements to OCR investigations, enforcement priorities, and litigation risks. (See below for more information)

For more information, please contact:

Dianne Pledgie
Principal
dianne.pledgie@powerslaw.com

Want to know more?

Below are upcoming trainings you may find helpful. Visit our Catalogue page for a full list.